URLhaus Database

You are currently viewing the URLhaus database entry for http://lejintian.cn/wp-admin/lm/CUBhsurjIYlmEDiyUA/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:189876
URL: http://lejintian.cn/wp-admin/lm/CUBhsurjIYlmEDiyUA/
URL Status:Offline
Host: lejintian.cn
Date added:2019-05-03 00:33:16 UTC
Last online:2019-05-06 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-03 00:34:03 UTC to ipas{at}cnnic[dot]cn)
Takedown time:3 days, 6 hours, 17 minutes Bad (down since 2019-05-06 06:51:30 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-04FILE_408302234699US_May_04_2019.docdoc 9547c3f40f790fab370c5620245c7736282c4931b82100c519746d8f3b072bd8Virustotal results 33.33% Heodo
2019-05-04DOC_0022170264US_May_04_2019.docdoc cf3d4fc7080d12f23a1a7718b0fdbcb958eef9121a01f094080652c4c5af354cn/a Heodo
2019-05-04LLC_107867291278US_May_04_2019.docdoc e46ab44563f129dfaae10e440d99832bcc0058052c2f8452d4e22f76a86619f9Virustotal results 33.33% Heodo
2019-05-04LLC_346107088616US_May_04_2019.docdoc 29fbe810f901708dac076960285cc4a1164efa16a4616e037e8d3096f2c54f4bVirustotal results 33.33% Heodo
2019-05-04FILE_2413730391US_May_04_2019.docdoc 3d27988d2bf5995fb39453cf9a94fd9ab6319ba0ffa17f3cb3b8e8583cf2327dn/a Heodo
2019-05-04FILE_871284075167US_May_04_2019.docdoc e35c59d2dc2d98f655064a3efc2e7a994e4efe4628f60a06e84fc079d8c2fe91Virustotal results 35.00% Heodo
2019-05-04Document_42628988658US_May_04_2019.docdoc 41455b1035cfa169e177dfc169342186b612047c266be25ba3e8d7475879f99fVirustotal results 33.87% 
2019-05-04Document_794751107421US_May_04_2019.docdoc f29605f7da73e128b8c8a3b3c984b6d2fad00a690d29fe40e88712fa1cd4c943Virustotal results 30.00% Heodo
2019-05-04INC_3560934824US_May_04_2019.docdoc f0160de6e608f33753cb1d6b18224e9501f0f82699d4d9c1dbcb61abd92b46f3n/a 
2019-05-04DOC_7658930878US_May_04_2019.docdoc e308c87030596d6f208f7166d05482820d0218e2d2f2dcb4d2b95044022583d4Virustotal results 31.67% Heodo
2019-05-03DOC_79533428869US_May_04_2019.docdoc d94ff5aadd33871bf10b2316e3d14e19520506724771f95749210248b7931effVirustotal results 32.08% 
2019-05-03Document_6156457523US_May_04_2019.docdoc 9134f010ba61c78c8dd064852b3d3245294c936e8a7c6c26577f24bbeb985971Virustotal results 30.51% Heodo
2019-05-03DOC_8041301771US_May_04_2019.docdoc 0282a70dabec4f4b6cc1f477cab7a97e23558677a0b6d8bb55f329b9719deb5en/a Heodo
2019-05-03FILE_21267313202US_May_04_2019.docdoc eeec0046cd334722d51b9db31e8c18d1d6ace4246c790bbbc311d553c2f3ddd4Virustotal results 33.90%Heodo
2019-05-03FILE_3135557030US_May_03_2019.docdoc 9f00e70566d4c513207f676149a70437674345f52f057b83af8553fb8b7ece4aVirustotal results 26.67% Heodo
2019-05-03FILE_605785644314US_May_03_2019.docdoc 0731dac1d684fd9c6150d9d0c20e52073cdf8b9a8a2afbe06578f553c315bc86n/a Heodo
2019-05-03Document_80175581095US_May_03_2019.docdoc 89f70f1ea8bb56015eb8427c1900918320be4468fdd858cd59c410ff5f6fc1f2Virustotal results 28.33% Heodo
2019-05-03FILE_4823757488US_May_03_2019.docdoc 96973059c987c115d57614d9f730f3acf54956b3c502610929bca5221e635134Virustotal results 28.81% 
2019-05-03FILE_368217565538US_May_03_2019.docdoc 47ff1922c8bf5e9e4944d5d3703858836ae1acbb1387c2cf3280abfe1eb20632Virustotal results 28.33% Heodo
2019-05-03FILE_9994983341US_May_03_2019.docdoc 47d5b493497550fbfa7b76608e82b40b7432ec6fd0efd5b162d1901a189133f9Virustotal results 29.51% Heodo
2019-05-03LLC_06436141116US_May_03_2019.docdoc 6acdb5b39fdd7d5976ee9480efb4121c18ad2eac2c99672e44f9b1ce729d0a5eVirustotal results 24.56% Heodo
2019-05-03FILE_89155271544US_May_03_2019.docdoc 79b6f593af071528bec7bdf1e1dc916bb1fb622dee27050b56b399c55c654cf0Virustotal results 29.51% Heodo
2019-05-03FILE_13413511692US_May_03_2019.docdoc 678b5fc437b1cd3e051dbc63130bdc93a77c4abc03ad2a337b7713648aa9ce78Virustotal results 30.00% Heodo
2019-05-03SCAN_84247591986US_May_03_2019.docdoc f029880d606aa137ede992ecafc9cb518d5e0464266b497cba4d10ddc6a6925fVirustotal results 29.51% Heodo
2019-05-03LLC_353777559769US_May_03_2019.docdoc 6c03ef96d9933ed865c770135fa52fddc780e30d5cddff4c4caff56561b2387dVirustotal results 29.51% Heodo
2019-05-03INC_3189790212US_May_03_2019.docdoc c210dbd9324b5c7aac98391d73e4dba9b552ed32a7463c91f5ee2b2a0132ec4bn/a Heodo
2019-05-03DOC_7610892984US_May_03_2019.docdoc 405e58903f88ee4859fc1ffd4d8449d2a8cb49ea316b6a7e98c6a0ca46239f24Virustotal results 31.15% Heodo
2019-05-03Document_462827279831US_May_03_2019.docdoc c8e8b66dc6ffec6967656987f6a3f563ce4d05ec39ed7b50553f014ec1c80e48Virustotal results 31.15% Heodo
2019-05-03LLC_3915167806US_May_03_2019.docdoc 7bba68ab02b42d9dea75497eacb1183e2ad6e6bd72969305dbaf8cd619ac2ce9n/a Heodo
2019-05-03LLC_7570683830US_May_03_2019.docdoc ea463dfde8a57310c7b88c38c7ed0168db56e53605cc287be2286a45c78c8434Virustotal results 31.67% Heodo
2019-05-03INC_424829156090US_May_03_2019.docdoc dcca578d9c6b6b2a130fc9d21ed872258ff71901fe4e3566e2990f5151d94f78Virustotal results 31.67% Heodo
2019-05-03LLC_967579937151US_May_03_2019.docdoc 990801c1de058647b506c19565ee7abf0c886af33defe87c185c91aa65f9b579Virustotal results 41.67% Heodo
2019-05-03INC_90901381225US_May_03_2019.docdoc 4146e3cf4f60248ab8855463ad47ac44eadfa77f85a93d219f31d7ee935d9da6Virustotal results 42.37% Heodo
2019-05-03DOC_7463630533US_May_03_2019.docdoc 8d811bece1938911aa657dc5292eb1d12e09c27c1c53b0933cd390e1713fa25bVirustotal results 38.33%